Killall::
Snapshot::
File::
C:\WINDOWS\system32\KHATRA.exe
C:\WINDOWS\system32\winwork.exe
Killall::
Snapshot::
File::
D:\KHATRA.exe
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54cde260-250f-11de-96cb-00034768309d}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6c425f0-2e51-11dd-960b-00034768309d}]
Killall::
Snapshot::
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6c425f0-2e51-11dd-960b-00034768309d}]